CVE-2026-77234 PUBLISHED

Improper input validation in FreeRTOS-Kernel timer command handling

Assigner: AMZN
Reserved: 20.08.2026 Published: 21.08.2026 Updated: 21.08.2026

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.3

Product Status

Vendor FreeRTOS
Product FreeRTOS-Kernel
Versions Default: unaffected
  • affected from 7.0.0 to 11.3.0 (incl.)

Credits

  • NVIDIA finder

References

Problem Types

  • CWE-863: Incorrect Authorization CWE

Impacts

  • CAPEC-233 (Privilege Escalation)